Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-47429

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4.1.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 57.7%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-47429


Contact Us

Shodan ® - All rights reserved